Home/Tools/Stripe Webhook Verifier
100% Free Developer Utility

Stripe Webhook Signature & Raw Buffer Verifier

AI editors like Cursor and Claude love writing await req.json() in Next.js webhooks. That small mistake alters whitespace and invalidates cryptographic signatures on every single transaction. Paste your route below to test for the 5 biggest webhook landmines.

Load sample:
Paste route handler code (route.ts)27 lines

What Happens If Your Webhook Fails?

When a user purchases your product, Stripe sends an HTTP POST event to your webhook. If your signature verification fails, the user is charged on Stripe, but your database never updates. Your customer is left stranded on a loading screen, sending angry emails asking why their account wasn't unlocked.

2 Launch Blockers Detected

Review the test failures below and apply the 1-click fix prompt.

Raw Body Buffer Check
ACTION REQUIRED

Your route appears to parse JSON before signature verification with req.json().

Fix: Change to "const body = await req.text();". Stripe requires the exact raw payload string to verify the cryptographic HMAC signature.

Stripe Signature Header Check
PASSED

Reads "stripe-signature" header from incoming request.

Fix: Verified.

Webhook Secret Storage
ACTION REQUIRED

Hardcoded Stripe webhook secret string detected (whsec_...).

Fix: Never hardcode your webhook secret. Load it from process.env.STRIPE_WEBHOOK_SECRET.

Signature Verification Call
PASSED

constructEvent is safely enclosed in try/catch.

Fix: Verified.

Event Acknowledgment Check
PASSED

Returns response acknowledging receipt.

Fix: Verified.

Want an automated scan across your whole codebase?

Stripe webhooks are just 1 of our 108 launch readiness checks. With the Founder Pass ($15 one-time), we inspect your auth flows, API routes, database policies, and dependencies in minutes.